Rechtliches

Auftragsverarbeitungsvertrag (AVV)

Zuletzt aktualisiert: 2026-09-06

Dieser Vertrag wird bei der Registrierung akzeptiert und gilt für jeden Tarif. Enterprise-Kunden können eine gegengezeichnete Fassung anfordern.

Data processing agreement under Art. 28 GDPR between the customer ("controller") and Teleroids.io ("processor") for the Caicle service.

1. Gegenstand und Dauer

The processor processes personal data on behalf of the controller to provide the Caicle service as described in the terms and the documentation. The agreement runs for the term of the service contract and ends with the deletion or return of the data under section 8.

2. Art und Zweck

Storage and processing of account and workspace data; collection, storage and analysis of company research data from public registers and the company's own filings; generation of scores, summaries and plans with machine-learning models; hosting, backup and support. Person research is limited by system rule to professional roles.

3. Datenarten und betroffene Personen

  • Data subjects: the controller's users; contact persons and executives of researched companies in their professional role; the controller's clients where the controller resells the service.
  • Types of data: name, business email, role and organisation of users; names, roles and professional contact details of executives and contact persons as published in registers, legal notices and company websites; usage and log data.
  • Special categories: none. Private-life data is out of scope by system rule.

4. Pflichten von Verantwortlichem und Auftragsverarbeiter

The processor processes personal data only on the controller's documented instructions, including the settings the controller chooses in the service, unless required to do so by law. The processor ensures that persons authorised to process the data are bound to confidentiality, implements the measures in section 6, supports the controller under sections 7 and 9, and informs the controller without undue delay if an instruction in its opinion infringes data-protection law. The controller is responsible for the lawfulness of the processing, including a legal basis for outreach and the information duties under Art. 13 and 14 GDPR, for which the service generates a notice on every dossier.

5. Unterauftragsverarbeiter

The controller gives general authorisation for the subprocessors listed below and in the trust centre. The processor informs workspace owners by email at least 30 days before adding or replacing a subprocessor; the controller may object on reasonable data-protection grounds, in which case either party may terminate the affected service. The processor imposes equivalent data-protection obligations on each subprocessor by contract.

ZweckAnbieterStandortGarantieSeit
Hosting, database and agent sandboxEU hosting providerEUDPA, ISO 270012026
Email deliveryTransactional email providerEUDPA2026
PaymentsStripeEU/USDPA, SCCs2026
Model inferenceModel provider (per configured key)EU or US depending on providerDPA, SCCs where applicable; bring-your-own key available2026
Web searchSearch providers (per configured key)VariesDPA where available; query text only2026
AnalyticsSelf-hosted, cookielessEUNo third party2026

6. Technische und organisatorische Maßnahmen

  • Encryption in transit (TLS) and at rest, including provider keys and MCP credentials
  • Tenant isolation through row-level security in the database
  • Agents and tools run in a sandbox with no route to the database and no shell
  • Outbound network access from the sandbox only through an egress allowlist
  • Role-based access control, least privilege for staff, and multi-factor authentication for administrative access
  • Logging of administrative actions, approvals and security events
  • Encrypted backups in the EU with regular restore tests
  • Secure development practice, dependency monitoring and a vulnerability disclosure contact

7. Unterstützung bei Betroffenenrechten

The processor supports the controller with appropriate technical and organisational measures in fulfilling requests from data subjects under Art. 15 to 22 GDPR, in particular through export and deletion functions in the service. Requests received directly by the processor are forwarded to the controller without undue delay.

8. Löschung und Rückgabe

At the end of the service the controller may export its data for 30 days. After that the processor deletes all personal data, including backups within the backup rotation period, unless the law requires longer storage. Deletion is confirmed on request.

9. Prüfung

The processor makes available the information necessary to demonstrate compliance with Art. 28 GDPR, including this agreement, the trust centre and available certifications of its hosting provider, and allows for and contributes to audits by the controller or an auditor mandated by the controller, with reasonable notice, during business hours and no more than once a year unless a supervisory authority requires otherwise.

10. Haftung

Liability follows Art. 82 GDPR and the liability provisions of the terms of service. Each party is responsible for the fines and damages attributable to its own breach of this agreement.